Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 11.0.0Upgrade Apache Tomcat to 9.0.90Upgrade Apache Tomcat to 10.1.25 | Nov 7, 2024 | Nov 7, 2024 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Jan 21, 2026 | Jan 20, 2026 |
| Debian | — | Upgrade tomcat10Upgrade tomcat9 | Sep 25, 2024 | Sep 25, 2024 |
| Redhat_linux | — | Upgrade apache-commons-netNo solution existsUpgrade glassfish-fastinfosetUpgrade tomcat-webappsUpgrade javassist-javadocUpgrade pki-core-debugsourceUpgrade xsomUpgrade idm-pki-symkeyUpgrade tomcat-el-3.0-apiUpgrade xalan-j2Upgrade ldapjdkUpgrade apache-commons-collectionsUpgrade idm-pki-serverUpgrade ldapjdk-javadocUpgrade jss-javadocUpgrade pki-core-debuginfoUpgrade jss-debuginfoUpgrade xmlstreambufferUpgrade python3-nssUpgrade idm-pki-toolsUpgrade glassfish-jaxb-runtimeUpgrade javassistUpgrade idm-pki-caUpgrade glassfish-jaxb-coreUpgrade python3-nss-debuginfoUpgrade glassfish-jaxb-txw2Upgrade tomcat-servlet-4.0-apiUpgrade jakarta-commons-httpclientUpgrade idm-pki-baseUpgrade pki-servlet-4.0-apiUpgrade jss-debugsourceUpgrade tomcat-docs-webappUpgrade xml-commons-resolverUpgrade tomcatUpgrade xerces-j2Upgrade idm-pki-kraUpgrade velocityUpgrade xml-commons-apisUpgrade idm-pki-tools-debuginfoUpgrade jackson-databindUpgrade slf4jUpgrade stax-exUpgrade tomcatjssUpgrade idm-pki-base-javaUpgrade tomcat-jsp-2.3-apiUpgrade apache-commons-langUpgrade glassfish-jaxb-apiUpgrade python-nss-docUpgrade jssUpgrade relaxngDatatypeUpgrade jackson-annotationsUpgrade pki-servlet-engineUpgrade jackson-jaxrs-providersUpgrade idm-pki-acmeUpgrade python3-idm-pkiUpgrade slf4j-jdk14Upgrade jackson-jaxrs-json-providerUpgrade tomcat-admin-webappsUpgrade resteasyUpgrade jackson-module-jaxb-annotationsUpgrade jackson-coreUpgrade idm-pki-symkey-debuginfoUpgrade bea-stax-apiUpgrade tomcat-libUpgrade python-nss-debugsource | Oct 31, 2024 | Sep 23, 2024 |
| Suse | — | Upgrade tomcatUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-el-3_0-apiUpgrade tomcat-webapps | Dec 5, 2025 | Oct 2, 2024 |
| Ubuntu | — | Upgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat10-java (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro) | Jun 11, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub